Split into setup-local.sh + setup-remote.sh, add RDP configuration

Renames bootstrap.sh to setup-local.sh to match its actual scope (the
travel laptop only) and adds setup-remote.sh for the machine you
Remote-SSH/RDP into, since that's a different machine's one-time setup
and was already living outside setup-local.sh's reach (same reasoning
as the existing Tailscale-SSH prerequisite).

setup-remote.sh configures GNOME's system-level RDP (works from a cold
GDM login screen, not just an existing session) restricted to the
tailscale interface via a ufw rule, a self-signed TLS cert, and RDP
credentials that are deliberately separate from the account password
and never cached - only prompted if unset. Shares step-tracking helpers
with setup-local.sh via a new lib.sh rather than duplicating them.

Tested the branching logic (credentials-already-set, RDP-already-
enabled, ufw-already-active-with-rule, ufw-inactive-confirm/decline)
against realistic stubbed command output. Caught and fixed a real bug
in the process: the inactive/active ufw check used a bare `grep -qi
active`, which also matches the substring inside "inactive" - it was
silently skipping the enable-confirmation gate and going straight to
adding a firewall rule on a firewall that was never turned on. Fixed
by anchoring the match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tommy Rantti 2026-09-26 21:25:19 +03:00
parent 9999e1da41
commit ef28afb9b8
4 changed files with 263 additions and 24 deletions

28
lib.sh Normal file
View file

@ -0,0 +1,28 @@
#!/usr/bin/env bash
# Shared step-tracking helpers for setup-local.sh and setup-remote.sh
STEP_NAMES=()
STEP_STATUS=()
STEP_DETAIL=()
step_ok() { STEP_NAMES+=("$1"); STEP_STATUS+=("OK"); STEP_DETAIL+=("${2:-}"); echo "[OK] $1"; }
step_skip() { STEP_NAMES+=("$1"); STEP_STATUS+=("SKIPPED"); STEP_DETAIL+=("${2:-}"); echo "[SKIPPED] $1 - ${2:-}"; }
step_fail() { STEP_NAMES+=("$1"); STEP_STATUS+=("FAILED"); STEP_DETAIL+=("${2:-}"); echo "[FAILED] $1 - ${2:-}"; }
section() { echo; echo "== $1 =="; }
# Prints the OK/SKIPPED/FAILED table. Returns 1 if any step failed, 0 otherwise.
# Does not exit and does not print anything past the table - callers add their
# own pass/fail wording and next-steps text.
print_summary_table() {
echo
echo "===================== summary ====================="
local any_failed=0
for i in "${!STEP_NAMES[@]}"; do
printf '[%-8s] %s\n' "${STEP_STATUS[$i]}" "${STEP_NAMES[$i]}"
[ -n "${STEP_DETAIL[$i]}" ] && printf ' %s\n' "${STEP_DETAIL[$i]}"
[ "${STEP_STATUS[$i]}" = "FAILED" ] && any_failed=1
done
echo "====================================================="
return "$any_failed"
}